/etc/cron.allow exists on a host and contains only the line `alice`. /etc/cron.deny exists too and lists `bob`. Which users may run crontab?
LPIC-1 Exam 102-500, objective 107. Administrative tasks hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct Every user except bob, because cron.deny takes effect first
Wrong. The order is the other way round: cron.deny is consulted only when cron.allow does not exist. With cron.allow present, cron.deny is ignored entirely.
Not correct No user at all, because the two files contradict each other
Wrong. The rule is a strict precedence, not a conflict. Nothing is disabled by having both files present.
Correct Only alice, because cron.allow exists and cron.deny is then ignored
Correct. If /etc/cron.allow exists, only the users named in it may use crontab, and /etc/cron.deny is not consulted. root is normally exempt from these restrictions.
Not correct alice and bob, because being named in either file grants access
Wrong. cron.deny lists users who are refused, never users who are granted. Naming someone there can only take access away.
Why
The rule: if /etc/cron.allow exists, it is an exclusive whitelist and /etc/cron.deny is ignored. If cron.allow does not exist, everyone may use crontab except users listed in cron.deny. If neither file exists, behaviour depends on the build — many distributions then allow only root. at uses the identical scheme with /etc/at.allow and /etc/at.deny.
Where this comes from
- Cited
- LPI exam objective 107.2
- What it says
- Configure user access to cron and at services.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked